MEDIUM · 6.7

CVE-2019-1730

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute comma...

Vulnerability Description

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside of the Guest Shell. The attacker must authenticate with valid administrator device credentials. The vulnerability is due to the incorrect implementation of a CLI command that allows a Bash command to be incorrectly invoked on the Guest Shell CLI. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Guest Shell prompt. A successful exploit could allow the attacker to issue commands that should be restricted by a Guest Shell account.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoNx-Os>= 7.0\(3\)i4, < 7.0\(3\)i4\(9\)
CiscoNexus 3000-
CiscoNexus 3100-
CiscoNexus 3100-Z-
CiscoNexus 3100V-
CiscoNexus 3200-
CiscoNexus 3400-
CiscoNexus 3500-
CiscoNexus 3524-X-
CiscoNexus 3524-Xl-
CiscoNexus 3548-X-
CiscoNexus 3548-Xl-
CiscoNexus 9000V-
CiscoNexus 92160Yc-X-
CiscoNexus 92300Yc-
CiscoNexus 92304Qc-
CiscoNexus 92348Gc-X-
CiscoNexus 9236C-
CiscoNexus 9272Q-
CiscoNexus 93108Tc-Ex-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1730?

CVE-2019-1730 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute comma...

How severe is CVE-2019-1730?

CVE-2019-1730 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1730?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 3000, Cisco Nexus 3100, Cisco Nexus 3100-Z, Cisco Nexus 3100V.